Google Cloud Security Engineer Exam Prep Training Course

Develop skills in IAM architecture, VPC Service Controls, data encryption, and threat posture management on Google Cloud.
Google Cloud Security Engineer Exam Prep Training Course

At a glance

Duration
5 days
Format
Classroom
Cities
Kuala Lumpur, London, Vienna, Istanbul, Madrid, Manama and more
Next session
5 – 9 October 2026, Kuala Lumpur
Average fee
5,800 €

Overview

The Google Cloud Security Engineer exam (Professional Cloud Security Engineer) tests whether a candidate can actually operate the Google Cloud console, gcloud CLI and Organization Policy Service under pressure, not just recite principles. This 5-day exam prep programme walks through each section of the official exam guide in the order Google publishes it: configuring access within a project and organization, securing communications and boundary protection, ensuring data protection, managing operations, and supporting regulatory requirements. Every day ends with timed scenario questions written in the exam's case-study style, so participants learn to spot the one Google-recommended answer among several technically possible ones. This course is delivered by Agile Leaders Training Center.

Who Should Attend

  • Engineers booked to sit the Professional Cloud Security Engineer exam within the next few months
  • Google Workspace and Cloud Identity administrators who own super-admin and group design
  • Platform teams that run landing zones built with the Cloud Foundation Toolkit or Terraform
  • SOC analysts moving onto Security Command Center Premium and Chronicle
  • Holders of the Associate Cloud Engineer badge aiming for their first professional-level credential

Departments and Industries

Useful wherever Google Cloud projects hold regulated or customer data.

  • Platform engineering groups operating GKE and Cloud Run estates
  • Banking teams bound by key-custody and audit-trail rules
  • Health data platforms running BigQuery analytics on patient records
  • Government bodies adopting Assured Workloads folders
  • Retail and media companies running high-traffic sites behind Cloud Load Balancing

Learning Objectives

By the end of this course, participants will be able to:

  • Choose between basic, predefined, custom and deny policies for a given gcloud scenario.
  • Draw a VPC Service Controls perimeter, add access levels and ingress/egress rules, and test it in dry-run mode.
  • Pick the correct key option (Google default, CMEK, CSEK, Cloud HSM or Cloud EKM) for a stated data requirement.
  • Build a Sensitive Data Protection inspection job and a de-identification template for a BigQuery table.
  • Read Security Command Center findings and route them to Pub/Sub for automated remediation.
  • Answer exam questions on Organization Policy constraints, Access Transparency and Key Access Justifications.

Course Agenda

Day 1: Exam Section 1 - Configuring Access

  • Exam format, question styles and how the case studies are scored
  • Cloud Identity, Google Cloud Directory Sync and SAML federation with an external IdP
  • Resource hierarchy: organization node, folders, projects and policy inheritance
  • Service accounts versus user accounts, impersonation and disabling key creation by constraint
  • Workload Identity Federation for GitHub Actions and AWS workloads, with a timed 15-question access-control quiz

Day 2: Exam Section 2 - Communications and Boundary Protection

  • Hierarchical firewall policies, network tags versus secure tags
  • Cloud Armor rules, preconfigured WAF signatures and adaptive protection
  • Identity-Aware Proxy for SSH, RDP and internal web apps
  • Private Service Connect, Private Google Access and Cloud NAT choices
  • VPC Service Controls perimeters, bridges and dry-run logs, with a timed network boundary case study

Day 3: Exam Section 3 - Data Protection

  • Sensitive Data Protection discovery, inspection and de-identification
  • Cloud KMS key rings, rotation periods, key versions and destroy scheduling
  • Cloud HSM, Cloud EKM and Key Access Justifications compared
  • Secret Manager versions, replication and IAM on individual secrets
  • Uniform bucket-level access, signed URLs and BigQuery column-level security, with a timed quiz on choosing the right encryption model

Day 4: Exam Section 4 - Managing Operations

  • Admin Activity, Data Access and Policy Denied audit logs; aggregated log sinks
  • Security Command Center tiers, detectors and mute rules
  • Binary Authorization attestations with Artifact Registry scanning
  • GKE hardening: Shielded Nodes, Workload Identity and Policy Controller
  • Incident playbook for a leaked service account key, with a timed operations and incident quiz

Day 5: Exam Section 5 - Regulatory Requirements and Full Mock

  • Assured Workloads, resource location restrictions and Access Approval
  • Organization Policy constraints most often asked in the exam
  • Full-length 50-question mock exam under timed conditions
  • Answer walkthrough explaining why distractor options are wrong
  • Personal weak-area map and booking checklist for the real exam

Practical Exercises

The following hands-on activities are suggested to reinforce each exam section in a live Google Cloud project.

  • Suggested activity: replace a downloaded service account key with Workload Identity Federation for a CI pipeline.
  • Suggested activity: put BigQuery and Cloud Storage inside a VPC Service Controls perimeter and read the dry-run violations.
  • Suggested activity: encrypt a bucket with a CMEK, rotate the key and observe which objects use which version.
  • Suggested activity: block unsigned images on a GKE cluster with Binary Authorization.

FAQs

What should candidates know before the first day?

Hands-on time in the Google Cloud console and gcloud, plus working knowledge of TCP/IP and public-key cryptography. The Associate Cloud Engineer level is a good baseline.

How many hours of study does the course cover?

Sessions run four to five hours a day, giving 20 to 25 hours in total, including four timed quizzes and one full mock exam.

When should I choose CMEK instead of Google default encryption?

Google default encryption needs no configuration. CMEK is chosen when you must control rotation, disable a key to make data unreadable, or show auditors who can use the key in Cloud KMS.

Conclusion

Candidates leave with every exam section rehearsed against Google's own service names and recommended patterns, a scored mock exam, and a clear list of topics to revise before booking the Professional Cloud Security Engineer exam.

credits: 5 credit per day

Course Mode: full-time

Provider: Agile Leaders Training Center

Showing 41-60 of 79 events
Image Location Dates Duration Mode Price Actions
Montreux Montreux Week 22, 2027
31 May – 4 June 2027
5 Days Onsite €7,500
Berlin Berlin Week 24, 2027
14 – 18 June 2027
5 Days Onsite €5,700
Lisbon Lisbon Week 24, 2027
14 – 18 June 2027
5 Days Onsite €5,700
New York New York Week 25, 2027
21 – 25 June 2027
5 Days Onsite €12,000
London London Week 26, 2027
28 June – 2 July 2027
5 Days Onsite €5,700
Seoul Seoul Week 26, 2027
28 June – 2 July 2027
5 Days Onsite €10,000
Abu Dhabi Abu Dhabi Week 26, 2027
28 June – 2 July 2027
5 Days Onsite €4,700
Abu Dhabi Abu Dhabi Week 27, 2027
5 – 9 July 2027
5 Days Onsite €4,700
Munich Munich Week 27, 2027
5 – 9 July 2027
5 Days Onsite €5,700
Rome Rome Week 28, 2027
12 – 16 July 2027
5 Days Onsite €5,700
Amsterdam Amsterdam Week 28, 2027
12 – 16 July 2027
5 Days Onsite €5,700
Doha Doha Week 28, 2027
18 – 22 July 2027
5 Days Onsite €5,500
Istanbul Istanbul Week 29, 2027
19 – 23 July 2027
5 Days Onsite €4,500
Barcelona Barcelona Week 30, 2027
26 – 30 July 2027
5 Days Onsite €5,700
Prague Prague Week 30, 2027
26 – 30 July 2027
5 Days Onsite €6,000
Manama Manama Week 30, 2027
1 – 5 August 2027
5 Days Onsite €4,700
Madrid Madrid Week 31, 2027
2 – 6 August 2027
5 Days Onsite €5,700
Vienna Vienna Week 32, 2027
9 – 13 August 2027
5 Days Onsite €5,700
Athens Athens Week 32, 2027
9 – 13 August 2027
5 Days Onsite €6,700
Bali Bali Week 32, 2027
15 – 19 August 2027
5 Days Onsite €5,700

Frequently asked questions

What does this course cover?

OverviewThe Google Cloud Security Engineer exam (Professional Cloud Security Engineer) tests whether a candidate can actually operate the Google Cloud console, gcloud CLI and Organization Policy Service under pressure, not just recite principles. This 5-day exam prep programme walks through each section of the official exam guide in the order Google publi…

Are training dates available?

Yes. Available dates and destinations are listed in the course dates section on this page.

How can I register?

Choose an available date on this page and complete the registration form, or send a programme enquiry.

Can I download the course brochure?

Yes. Use the brochure download link provided on this page.

This course by city